Splunk SOAR

Entity Risk Reduction upon False Positive disposition

pruthviraj_k_m
Explorer

Hi All,

I am trying to build a playbook that reduces the risk of an entity in any of the splunk notable only when the notable disposition is set to False Positive by the analyst. I need to negate the same amount of risk added by the finding score as well as intermediate finding score. Is it possible to do so? What is the process for that?

I did find an approach to post the risk event but not able to create any event. Additionally, I want to know how to calculate the amount of risk to be negated?

Thanks!

Labels (1)
0 Karma

phanTom
SplunkTrust
SplunkTrust

@pruthviraj_k_m I think I managed to find the docs around what actions are available on the ES Connector in SOAR and I can't see a direct "Risk Modifier" action. 

There is an API for ES Risk where you can update risk but I can't see if that's an action already available or whether you may need to build the capability into SOAR. 

My methodology for what you are trying to achieve:

1. Upon container close run a playbook to check for disposition
2. If "false positive" identify the risk object (asset/identity)
3. Run search in the risk index to ascertain the score that was added
4. Calculate the score and pass the - value (e.g. -40) into the reduction action, along with the relevant entity
5. Check for success


-- Hope this helps, if so consider leaving some Karma. Even better is if this fixed your issue, that you mark as a solution for others to find. Happy SOARing!! ---
0 Karma

phanTom
SplunkTrust
SplunkTrust

@pruthviraj_k_m you are on the right track with the risk event to reduce the risk score AFAIK. There should be an event in the risk index that shows the entity it's assigned to and the amount of risk applied. You will need to run a search from SOAR to find the risk addition using the information in the container and then perform the relevant risk reduce after. 


You may also need to be aware if a risk modifier was provided to the score, but if the total score added is all you want to then remove, I think you are good with this approach. 

-- Hope this helps, if so consider leaving some Karma. Even better is if this fixed your issue, that you mark as a solution for others to find. Happy SOARing!! ---
0 Karma

pruthviraj_k_m
Explorer

Thanks @phanTom .

I want to know, if we can use ES's risk modifier action in our playbook to reduce the overall risk score of an entity? If so, should we just negate whatever the finding score that we have received in the splunk notable or there exists any calculation to find out how much risk should be reduced?

 

0 Karma

phanTom
SplunkTrust
SplunkTrust

@pruthviraj_k_m unfortunately I don't have a SOAR instance attached to an ES instance and I can't see a way to get the ES App onto my current SOAR Sandbox. 

However, if there is an action to reduce risk on an entity by a value then all you should need to do is find the score assigned at the time of the alert (or could be multiple intermediate findings) so I would recommend running a search for all Risk events for the entity in the risk index, then you should be able to understand the value that was added, then pass that into the risk modification action. 

-- Hope this helps, if so consider leaving some Karma. Even better is if this fixed your issue, that you mark as a solution for others to find. Happy SOARing!! ---
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Analytics Workspace removal in Splunk 10.6

In Splunk Cloud Platform and Splunk Enterprise 10.6, Analytics Workspace is removed from product and no longer ...

Vibe-coding, AI, and Splunkcraft: Highlights from the .conf26 Builder Bar

If you stopped by the Builder Bar at .conf26, thank you! This year, we brought ...